| WN11-00-000031 - Windows 11 systems must use a BitLocker PIN for pre-boot authentication. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-00-000065 - Unused accounts must be disabled or removed from the system after 35 days of inactivity. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION |
| WN11-00-000100 - Internet Information System (IIS) or its subcomponents must not be installed on a workstation. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000120 - The TFTP Client must not be installed on the system. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000135 - A host-based firewall must be installed and enabled on the system. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000155 - The Windows PowerShell 2.0 feature must be disabled on the system. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000175 - The Secondary Logon service must be disabled on Windows 11. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000210 - Bluetooth must be turned off unless approved by the organization. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-AC-000030 - The minimum password age must be configured to at least 1 day. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-AC-000035 - Passwords must, at a minimum, be 14 characters. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-AU-000030 - The system must be configured to audit Account Management - Security Group Management successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000035 - The system must be configured to audit Account Management - User Account Management failures. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WN11-AU-000040 - The system must be configured to audit Account Management - User Account Management successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-AU-000065 - The system must be configured to audit Logon/Logoff - Logoff successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-AU-000075 - The system must be configured to audit Logon/Logoff - Logon successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000081 - Windows 11 must be configured to audit Object Access - File Share failures. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000100 - The system must be configured to audit Policy Change - Audit Policy Change successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000105 - The system must be configured to audit Policy Change - Authentication Policy Change successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000120 - The system must be configured to audit System - IPsec Driver failures. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000150 - The system must be configured to audit System - Security System Extension successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000505 - The security event log size must be configured to a value that holds at least one week's worth of audit records. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000565 - Windows 11 must be configured to audit other Logon/Logoff Events Failures. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000580 - Windows 11 must be configured to audit MPSSVC Rule-Level Policy Change Failures. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000588 - Windows 11 must be configured to audit sensitive privilege use failures. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-CC-000005 - Camera access from the lock screen must be disabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000030 - The system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000085 - Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000115 - Systems must at least attempt device authentication using certificates. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000145 - Users must be prompted for a password on resume from sleep (on battery). | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-CC-000150 - The user must be prompted for a password on resume from sleep (plugged in). | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-CC-000206 - Windows Update must not obtain updates from other PCs on the internet. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000295 - Attachments must be prevented from being downloaded from RSS feeds. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000305 - Indexing of encrypted files must be turned off. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000355 - The Windows Remote Management (WinRM) service must not store RunAs credentials. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-CC-000370 - The convenience PIN for Windows 11 must be disabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-SO-000015 - Local accounts with blank passwords must be restricted to prevent access from the network. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-SO-000165 - Anonymous access to Named Pipes and Shares must be restricted. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-SO-000190 - Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-SO-000215 - The system must be configured to meet the minimum session security requirement for NTLM SSP based clients. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-SO-000230 - The system must be configured to use FIPS-compliant algorithms for encryption, hashing, and signing. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-SO-000240 - The default permissions of global system objects must be increased. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-SO-000260 - User Account Control must be configured to detect application installations and prompt for elevation. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-SO-000265 - User Account Control must only elevate UIAccess applications that are installed in secure locations. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-UC-000020 - Zone information must be preserved when saving attachments. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WNDF-AV-000020 - Microsoft Defender AV must be configured to scan all downloaded files and attachments. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000024 - Microsoft Defender AV must be configured to scan archive files. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000042 - Microsoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Low. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000044 - Microsoft Defender AV must block credential stealing from the Windows local security authority subsystem. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000064 - Microsoft Defender AV must enable script scanning. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000073 - Microsoft Defender AV must set cloud protection level to High. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |